We rebuilt the Coffee Day fraud as a ledger. Our AI flagged every entry.
A reconstruction of the fraud patterns NFRA found in the Coffee Day group — and a test of whether full-population AI testing surfaces what sampling did not.
What this is: a reconstruction, not real data. No company's general ledger is public — not Coffee Day's, not anyone's. What is public is NFRA's order against the auditors, which describes the fraudulent entries in detail. We rebuilt a ledger from that description and ran Auraium over it.
The question we wanted answered: would an AI running across 100% of the transactions have surfaced what a real audit team, working from samples, did not?
What NFRA found
In August 2023, NFRA issued orders against the auditors of the Coffee Day group. The findings, in the regulator's own words:
- ₹3,535 crore was diverted from seven CDEL subsidiaries to MACEL, a promoter-owned entity
- The diversion was routed through complex intra-group circular transfers
- Outstanding receivables from MACEL were understated using uncashed cheque entries booked as loan repayments
- The auditors were charged with failing to detect evergreening of loans through structured circular transactions
The auditors did not miss this because they were negligent in some obvious way. They missed it because each individual entry, viewed alone, looked like ordinary inter-company activity. That is exactly what sampling is bad at.
How we rebuilt it
We generated a synthetic general journal for a fictional beverage group — 2,659 rows covering FY 2019-20. Ordinary operating activity makes up the bulk of it: sales, purchases, payroll, rent, vendor payments, with realistic log-normal amounts and weekday-skewed dates.
Into that we seeded 59 entries reproducing the four patterns NFRA described:
| Pattern | Entries | What it looks like in the ledger |
|---|---|---|
| Circular intra-group transfers | 32 | Round-sum advances moving through two or three subsidiaries over a few days, ending at the promoter-owned entity |
| Uncashed cheque "repayments" | 7 | Credits to the related-party loan account referencing a cheque number, clustered in Q4 |
| Evergreening | 12 | A repayment received, then a near-identical fresh disbursal to the same entity days later |
| Period-end manual journals | 8 | Large adjustment entries posted on quarter-end and year-end dates |
| Total seeded | 59 | 2.22% of the file |
The seeded proportion was deliberately in the range a real ledger would produce, so the test wasn't trivial. We then uploaded it to Auraium as a General Journal and ran a standard audit — no special configuration, no tuning for this file.
The result
| Pattern | Seeded | Caught |
|---|---|---|
| Circular intra-group transfers | 32 | 32 |
| Uncashed cheque repayments | 7 | 7 |
| Evergreening | 12 | 12 |
| Period-end manual journals | 8 | 8 |
| Total | 59 | 59 |
Every flagged entry came with a written explanation: what the entry was, why it was unusual, which red flags applied, what could not be determined from the data, and three specific next steps for the auditor.
What this does not prove
Auraium caught these primarily on magnitude and timing, not on structure. The seeded transfers were ₹2.5–15 crore in a ledger where the median entry was ₹85,000. The system flagged them as extreme outliers against the account baseline and as period-end postings. It did not announce "this is a circular transfer" or "this is evergreening" — it announced "this entry is deeply abnormal for this account, here is why, go look at it."
For an auditor, that distinction matters less than it sounds. The output is a shortlist of entries warranting documentation and follow-up, which is precisely what the audit standards require and precisely what was absent in the NFRA orders. But we are not claiming pattern recognition we have not demonstrated.
This is synthetic data. We built the ledger, which means we knew what was in it. It is a controlled test of detection, not evidence of performance on any real client file.
Why this matters for your firm
Read the NFRA orders closely and notice what they actually punish. Not "you failed to catch a fraud." They punish insufficient audit evidence, inadequate documentation, and failure to apply professional skepticism.
Under Section 132(4) of the Companies Act, proven professional misconduct carries a penalty of not less than ₹1 lakh — extending to five times fees received for an individual, ten times for a firm — plus debarment from audit work for six months to ten years. Real orders have landed at ₹5 lakh with a five-year ban, and ₹50 lakh on a firm with ₹10 lakh on the engagement partner personally.
NFRA's jurisdiction covers Public Interest Entities, so most SME audit work sits outside it. But Section 143(12) — the obligation to report fraud of ₹1 crore or more — applies to every statutory auditor of every company, and NFRA has stated publicly that auditors are not meeting it.
Sampling gives you a defensible answer to "did you look?" only for the 5–20% you sampled. Full-population testing gives you a timestamped record that you examined every entry, flagged the ones that mattered, and documented why.
That is the actual product. Not catching more fraud — being able to show what you looked at.
Try it on your own data
We will run one of your client ledgers free. Export it as CSV or Excel, anonymise it if you prefer — the counterparty names don't matter to the detection. We return the full report within 24 hours.
Your data is deleted after the run, never used for training, and we'll sign an NDA before you send anything.